Privacy Policy
1. Information We Collect
We collect information in the following categories:
- Account and identity data. Information you provide when you register or manage an account, such as your name, business email address, organization name, role, and authentication credentials.
- Usage data. Information about how you interact with the platform, such as log timestamps, device and browser type, IP address, pages or features accessed, and diagnostic or performance data to operate and secure the Services.
- Compliance and customer content. Data you or your organization upload, enter, or generate in the platform in connection with governance, risk, and compliance activities—such as policies, controls, assessments, evidence metadata, and related files. This may include sensitive or regulated information that your organization chooses to store in TailoredGRC.
We do not target or market our Services to individuals in the European Union for the purpose of collecting personal data from EU residents, and we design our operations so that customer data remains in the United States as described below.
2. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Services, including account setup, authentication, hosting, backups, customer support, and fulfillment of our agreement with your organization.
- Improve and develop the platform, including security monitoring, troubleshooting, analytics in aggregated or de-identified form where appropriate, and product improvement.
- Communicate with you, including service-related notices, administrative messages, and (where permitted) information about features or offerings. You may opt out of non-essential communications where applicable.
- Comply with law and enforce our terms, including fraud prevention, protecting rights and safety, and responding to lawful requests.
3. Data Storage and Security
We maintain United States–only data residency for the TailoredGRC platform: customer data is stored and processed within the U.S. and is not transferred to the European Union or other regions for hosting purposes as part of our standard service.
Our infrastructure uses providers such as Supabase (database and related backend services) and cloud resources hosted in AWS US East (N. Virginia, us-east-1). We implement administrative, technical, and organizational safeguards appropriate to the sensitivity of the data we handle, including encryption in transit (e.g., TLS) and encryption for data at rest where supported by our stack, access controls, and ongoing security practices.
No method of transmission or storage is completely secure; we strive to protect your information using commercially reasonable measures consistent with our role as a B2B compliance platform.
4. Data Sharing
We do not sell your personal information. We share information only as described in this policy and as needed to operate the Services.
We use a limited set of third-party processors, who are contractually obligated to protect information and process it only on our instructions:
- Stripe — payment processing and billing for subscriptions and related transactions.
- Anthropic — optional AI-assisted features, where prompts or content you submit may be processed to generate responses within the product, subject to our agreements and safeguards.
- Supabase — database, authentication, and related infrastructure for hosting and operating the application.
We may also disclose information if required by law, to protect our rights or users, or in connection with a merger, acquisition, or asset sale, subject to appropriate confidentiality obligations.
5. HIPAA Compliance
TailoredGRC is built to support organizations that handle sensitive compliance information. Where a customer is a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA) and intends to use the Services with protected health information (PHI), a Business Associate Agreement (BAA) may be required and is available as appropriate for qualifying enterprise arrangements.
PHI should only be uploaded or processed in the platform in accordance with your organization’s policies and the terms of your agreement with TailoredGRC. Customers are responsible for determining whether their use of the Services is appropriate for their regulatory obligations and for configuring access and use in line with HIPAA and other applicable rules.
6. Data Retention
We retain customer account data and content for as long as your subscription is active and for a reasonable period thereafter to fulfill legal, accounting, or backup obligations, unless a different period is specified in your agreement.
Upon request from an authorized account representative, or as required by contract or law, we will work with you to delete or return customer data in accordance with our technical capabilities and retention schedules. Some information may persist in encrypted backups for a limited period before automatic deletion.
7. Your Rights
Depending on your role and applicable law, you may have the right to:
- Request access to personal information we hold about you in connection with the Services;
- Request correction of inaccurate information;
- Request deletion of your information, subject to legal and contractual exceptions;
- Object to or limit certain processing, where applicable.
Because TailoredGRC is primarily a B2B service, many requests may need to be coordinated through your organization’s administrator. To exercise these rights, contact us using the information below.
8. Cookies and Tracking
We use minimal cookies and similar technologies that are largely functional in nature—for example, to keep you signed in, maintain session security, and remember essential preferences. We do not use invasive cross-site tracking for advertising as a core part of this policy; any future analytics or marketing cookies would be disclosed and, where required, consented to in line with applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. If changes are material, we will provide additional notice as appropriate (for example, by email or an in-product notice). Your continued use of the Services after the effective date of the revised policy constitutes acceptance of the updated terms, except where prohibited by law.
10. Contact Information
If you have questions about this Privacy Policy, our practices, or your data rights, please contact us:
TailoredGRC
Missouri, United States
Website: https://tailoredgrc.com/
Privacy inquiries: privacy@tailoredgrc.com